Module 3 of StartCloud's Microsoft 365 Security Essentials learning pathway, in six short units with a knowledge check: what preset security policies bundle (anti-spam, anti-malware, anti-phishing, Safe Links, Safe Attachments), why presets beat hand-tuning for most SMBs, which licences include what, and how to turn them on in the Microsoft Defender portal.
Turning On Preset Security Policies
One switch, a whole stack of protection
Open the email security settings in Microsoft 365 and you will find policy pages for anti-spam, anti-malware, anti-phishing, Safe Links, and Safe Attachments, each with dozens of dials. In theory you could tune every one of them yourself. In practice, almost nobody should, because half-finished tuning is how gaps creep in.
Preset security policies are Microsoft's answer. They bundle nearly all of those protections into two ready-made profiles, Standard and Strict, with settings chosen by Microsoft based on what its filters see across billions of mailboxes. You pick who each profile applies to, and that is essentially the whole job.
The clever bit is what happens afterwards. The settings inside a preset are locked and maintained by Microsoft, so when the threat landscape shifts or a best practice changes, your protection updates automatically. A custom policy you hand-built in 2023 is still sitting exactly where you left it in 2023. For most small and medium businesses, that alone settles the argument.
Ordering the set menu at a good restaurant is not a cop-out, it is trusting a kitchen that cooks these dishes hundreds of times a night. Presets are the set menu of email security. You could order a la carte and season everything yourself, but the kitchen sees more phishing emails before breakfast than your business will in a decade.